CVE-2019-12068 PUBLISHED

In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next opcode. This can lead to an infinite loop if the next opcode is empty. Move the existing loop exit after 10k iterations so that it covers no-op opcodes as well.

EPSS 0.09% · 25.2th percentile

Risk Scores

EPSS Score
0.09%
25.2th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSqemu0, 1.5.0+dfsg-3ubuntu5, 1.5.0+dfsg-3ubuntu6
Ubuntu:16.04:LTSqemu0, 1:2.3+dfsg-5ubuntu9, 1:2.3+dfsg-5ubuntu10
Ubuntu:18.04:LTSqemu0, 1:2.10+dfsg-0ubuntu3, 1:2.10+dfsg-0ubuntu4
Ubuntu:20.04:LTSqemu0, 1:4.0+dfsg-0ubuntu9, 1:4.0+dfsg-0ubuntu10

Timeline

References

Open in Interactive Console →